mega: fall back to password login when stored session is expired - #10006
Open
xiao115255 wants to merge 1 commit into
Open
xiao115255 wants to merge 1 commit into
xiao115255 wants to merge 1 commit into
Conversation
rclone#9952 When a mega remote is configured with a stored session (session_id and master key) and that session has expired on the server side, LoginWithKeys fails with the ESID or EAGAIN sentinel after go-mega's internal retries exhaust. Previously rclone surfaced this as "login with previous auth keys failed" and gave up, even though valid user/pass credentials were still configured, leaving the user to run rclone config reconnect manually. Extract the login flow into a login method which falls back to MultiFactorLogin when the stored session is rejected as invalid or expired, and persists the fresh session in the config so subsequent runs don't repeat the failed login. Add isSessionExpiredErr to identify the sentinels that mean the stored session is no longer usable, and unit tests pinning that classification down. Fixes rclone#9952 Co-Authored-By: Claude Code <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What & Why
When a
mega:remote is configured with a stored session (session_idandmaster_key) and that session has expired server-side,LoginWithKeysfails with theESIDorEAGAINsentinel aftergo-mega's internal retries exhaust. Until now rclone surfaced this aslogin with previous auth keys failedand gave up, even though a validuserandpasswere still configured, leaving the user to runrclone config reconnectmanually. Repeated MEGA‑3responses eventually corrupt the response buffer and the user seesunexpected end of JSON input.Extracted the login flow into a
loginmethod that falls back toMultiFactorLoginwhen the stored session is rejected as invalid or expired, and persists the fresh session in the config so subsequent runs don't repeat the failed login.isSessionExpiredErridentifies theEAGAIN(‑3) andESID(‑15) sentinels as the signals to re-authenticate.Addresses #9952 acceptance criteria:
How Tested
go build ./backend/mega/andgo vet ./backend/mega/— clean.RCLONE_CONFIG=/notfound go test -count=1 ./backend/mega/— pass, including the newTestIsSessionExpiredErrtable test which pins downEAGAIN/ESID(and wrapped variants) as session-expired, whileEACCESS(‑11),EARGS,EOVERQUOTA, and unrelated errors are not.End-to-end repro on a
mega:remote with a bogussession_id:Before (
master):After (this branch):
The test uses a non-existent user so MEGA also rejects the password fallback; with valid credentials,
MultiFactorLoginsucceeds andlsdproceeds. The point is the control flow: whenLoginWithKeysfails withESID/EAGAIN, the backend now recovers via the password rather than giving up immediately.Full backend tests against a real
TestMega:remote (the integration test suite) could not be run here as no MEGA credentials are available. The new unit test covers the error-classification behavior the fallback depends on; the auth path itself is unchanged on success and is exercised by the existingTestIntegrationagainst a real remote in the maintainer's CI.Known Limitations
srvstill holds the now-stalesid/kfrom go-mega, which a follow-up could refresh by callingloginfromshouldRetryor fromfindRoot. Filing that as a separate issue if the maintainer wants it.EAGAINis a "try again" sentinel; in the rare case MEGA returns-3for a transient server overload rather than an expired session, this fix triggers one extra password login attempt. The cost is bounded (one attempt, no loop), and the issue's debug log confirms-3here is in fact the expired-session case.AI Disclosure
This PR was prepared with AI assistance (Claude Code), reviewed and submitted by @xiao115255.